The quote shows "datacenter France." Legal approves. Then audit asks: where do admin logs, nightly snapshots, default CDN, support connecting from which country go? Silence. The French flag on the homepage describes the starting point, not the full route.
In modern hosting, your data does not "live" in one place. It moves, copies, gets monitored. Compliance — and promised sovereignty — play out on that graph, not on a map pin.
Beyond the datacenter: six steps to trace
1. Production. VM, shared hosting, bucket — the visible brick.
2. Replication. Inter-AZ or inter-region HA: where is the hot copy?
3. Backups. Same site, other region, other country? How encrypted?
4. Logs and monitoring. Centralized at a US SaaS? Retention where?
5. CDN / WAF / anti-DDoS. Traffic and sometimes content cross global PoPs.
6. Support and admin. Bastion access, tickets, remote hands — who touches what, from where?
| Step | Question | Risk if vague |
|---|---|---|
| Production | Region contractually locked? | Failover to cheaper region |
| Backups | Copies outside initial jurisdiction? | Undocumented transfer |
| CDN | Static content served from US? | Extended "in transit" data |
| Subcontractors | Up-to-date list in DPA? | Cloud Act unaddressed |
EU flag vs subcontractor chain
A "French" host may rely on hypervisor, object storage, managed DNS, or backup tools from a US player. Registered office is not enough.
Ask for the DPA with subprocessor annexes, not the "100% European" slide. Cross-check OVHcloud, Infomaniak, or Hetzner: each documents scope and regions differently.
The flag reassures buyers. The architecture diagram reassures auditors.
The summit: location is read in copies, not slogans
Decide and move forward without blind spots
Draw your flow: user → app → database → backup → restore test. For each arrow, note jurisdiction and subcontractor.
Lock region at order time, disable unnecessary replication, require up-to-date DPA.
See our directory and health data HDS article for sensitive projects.
Frequently asked questions
Is the flag on the website enough for GDPR compliance?
No. GDPR requires transparency on the full processing chain, including subprocessors and transfers outside the EU. The primary datacenter is only one step.
Where can copies of my data go without me knowing?
Backups, cross-region replication, centralized logs, CDN, support ticketing, anti-DDoS tools, panel analytics — each layer can involve another jurisdiction.
How do you get proof of location?
Contract + DPA listing subprocessors, locked region choice, technical architecture diagram from sales engineering, and rejection of default multi-region options.
Does a European host guarantee no Cloud Act exposure?
Not automatically. If a US parent or subcontractor has technical access to data, extraterritorial legal risk must be handled contractually and architecturally.
Next time someone shows you a flag, ask for the copy diagram — not the datacenter map.
